Bug 1929479 (CVE-2021-20250) - CVE-2021-20250 wildfly: Information disclosure due to publicly accessible privileged actions in JBoss EJB Client
Summary: CVE-2021-20250 wildfly: Information disclosure due to publicly accessible pri...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2021-20250
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1927289 1929559
TreeView+ depends on / blocked
 
Reported: 2021-02-17 02:45 UTC by Kunjan Rathod
Modified: 2021-07-15 15:26 UTC (History)
67 users (show)

Fixed In Version: jboss-ejb-client 4.0.39
Clone Of:
Environment:
Last Closed: 2021-03-16 19:20:07 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2021:0872 0 None None None 2021-03-16 13:44:08 UTC
Red Hat Product Errata RHSA-2021:0873 0 None None None 2021-03-16 13:36:20 UTC
Red Hat Product Errata RHSA-2021:0874 0 None None None 2021-03-16 13:40:08 UTC
Red Hat Product Errata RHSA-2021:0885 0 None None None 2021-03-16 13:19:59 UTC
Red Hat Product Errata RHSA-2021:0974 0 None None None 2021-03-23 14:18:40 UTC
Red Hat Product Errata RHSA-2021:2755 0 None None None 2021-07-15 15:26:00 UTC

Description Kunjan Rathod 2021-02-17 02:45:02 UTC
It was found that JBoss EJB client for WildFly has publicly accessible privileged actions which may lead to information disclosure vulnerability.

Comment 5 Carlo de Wolf 2021-02-22 14:38:45 UTC
Affects 4.0.38, fixed in 4.0.39 via https://github.com/wildfly/jboss-ejb-client/pull/503.

Comment 6 Ted Jongseok Won 2021-02-24 02:57:45 UTC
This vulnerability is out of security support scope for the following product:
 * Red Hat JBoss Operations Network 3

Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.

Comment 7 errata-xmlrpc 2021-03-16 13:19:52 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2021:0885 https://access.redhat.com/errata/RHSA-2021:0885

Comment 8 errata-xmlrpc 2021-03-16 13:36:11 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7

Via RHSA-2021:0873 https://access.redhat.com/errata/RHSA-2021:0873

Comment 9 errata-xmlrpc 2021-03-16 13:40:04 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8

Via RHSA-2021:0874 https://access.redhat.com/errata/RHSA-2021:0874

Comment 10 errata-xmlrpc 2021-03-16 13:43:58 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6

Via RHSA-2021:0872 https://access.redhat.com/errata/RHSA-2021:0872

Comment 11 Product Security DevOps Team 2021-03-16 19:20:07 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-20250

Comment 13 errata-xmlrpc 2021-03-23 14:18:35 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.4.6

Via RHSA-2021:0974 https://access.redhat.com/errata/RHSA-2021:0974

Comment 14 errata-xmlrpc 2021-06-02 14:23:49 UTC
This issue has been addressed in the following products:

  Red Hat EAP-XP via EAP 7.3.x base

Via RHSA-2021:2210 https://access.redhat.com/errata/RHSA-2021:2210

Comment 15 errata-xmlrpc 2021-07-15 15:25:58 UTC
This issue has been addressed in the following products:

  Red Hat EAP-XP 2.0.0 via EAP 7.3.x base

Via RHSA-2021:2755 https://access.redhat.com/errata/RHSA-2021:2755


Note You need to log in before you can comment on or make changes to this bug.